GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Public Institution

Country
Turkey
Fine
N/A
Date
2018-06-28
Sector
Public Sector
Articles
Art. 7 of the DPL

Insufficient technical and organisational measures to ensure information security

A public officer has requested the Data Controller, which is a public institution, to destroy the data pertaining to an investigation case that has been conducted on the data subject. The Institution has rejected the request. The Authority decided that the term pertaining to the storage of personal files of public officers has not been expired pursuant to the legislation, and therefore has not ruled any fines. Authority: Turkish Data Protection Authority (KVKK)